Impact
Improper input validation in Chrome’s Viz rendering component allows an attacker who has already compromised the renderer process to bypass system access restrictions by loading a specially crafted HTML page. The vulnerability does not depend on additional user interaction and can enable elevated privileges or unauthorized access to local resources from a web page.
Affected Systems
The issue affects Google Chrome versions earlier than 155.0.8059.39. Users running these builds on any platform are susceptible because the renderer process is granted higher privileges than regular web content.
Risk and Exploitability
The vulnerability carries a medium severity rating and is not listed in the CISA KEV catalog. EPSS data is not available, so the exact probability of exploitation is unknown. The likely attack vector is remote: an attacker who can execute code in the renderer, such as through a malicious website or compromised local content, can craft an HTML payload that triggers the improper validation and lifts the access restrictions. The attacker would need to deliver the payload to a compromised renderer, after which the system access boundaries can be bypassed.
OpenCVE Enrichment